Description
The WebSocket functionality in Storybook’s dev server, used to create and update stories, is vulnerable to WebSocket hijacking. This vulnerability only affects the Storybook dev server; production builds are not impacted.
Recommendation
Update the storybook package to the latest compatible version. Followings are version details:
Affected version(s): **>= 10.0.0-beta.0, < 10.2.10 >= 8.7.0-alpha.0, < 9.1.19 >= 8.1.0, < 8.6.17** Patched version(s): **10.2.10 9.1.19 8.6.17**
References
Could your website be exposed too?
SmartScanner can check your website for Storybook Dev Server is Vulnerable to WebSocket Hijacking and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Cline Kanban Server has a Cross-Origin WebSocket Hijacking Vulnerability - CVE-2026-44211
- axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge - CVE-2026-44495
- @elgentos/magento2-dev-mcp vulnerable to command injection - CVE-2026-5603
- pdfmake is vulnerable to server-side request forgery (SSRF) - CVE-2026-26801


